Keptn v1 reached EOL December 22, 2023. For more information see https://bit.ly/keptn

Vulnerability Bulletins

Disclosed security vulnerabilities and their mitigation.

Keptn-Vulnerability-2023-001

Supply chain vulnerability in Keptn 0.1.0 to 0.8.2 due to deleted Google Storage bucket by Helm

Keptn-Vulnerability-2022-001

Webhook Service for Keptn is vulnerable to token leaks and access the Kubernetes APIs

Keptn-Vulnerability-2021-001

JMeter Service for Keptn is vulnerable to log4shell

Keptn-Vulnerability-2020-002

RBAC cluster-admin role given to Keptn services by default

Keptn-Vulnerability-2020-001

Keptn is shipping an outdated and unsupported version of Istio